|
D-137 tier 2: wire --privileged escalation (run BLOCKED by the auto-mode classifier)
--privileged retries a remote probe with `sudo -n` ONLY where the unprivileged probe returned `unreadable`, keeping the privileged surface as small as ruling 3 keeps the search surface. Metadata only; the T22 metadata-only guard still passes; verified inert (zero escalations) when nothing is unreadable. The operator approved the privileged read, but the auto-mode classifier denied the remote-sudo shape -- the same wall the 2026-07-23 close recorded, whose noted fix is manual permission mode. NOT worked around: reading a root-owned directory is exactly the privilege being denied, so any alternative would fail identically or misrepresent the result. SEC-022 shadow-store contents and the SEC-020 region secrets stay UNCONFIRMED; the sweep reports them as E0 UNREADABLE FAILs, which is the correct outcome for an audit that could not look. Also de-staled the docstring tier table (tier 2 is built). Harness 35/35, gauntlet ALL GREEN (80), repo-lint 0-fail. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HvCyrwvYTTcDYnRErfMsNf |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260726-d137-tier1.md |
|---|
| scripts/creds-matrix.py |
|---|